CVE-2024-11044: AUTOMATIC1111 Stable-Diffusion-Webui

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

Affected products

Published 2025-03-20. Last modified 2026-06-17.